Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·pA3Wqi…g5NwSummary
The ClickFake Interview campaign is an active cyberespionage operation attributed with high confidence to Famous Chollima, a North Korean state-sponsored threat actor linked to the Reconnaissance General Bureau and the broader Lazarus Group umbrella. Targets are cryptocurrency and Web3 professionals lured via fake job recruitment on LinkedIn, Telegram, and Discord, then induced through a ClickFix social engineering trick to execute terminal commands that install the PylangGhost (Windows) or GolangGhost (macOS) remote access trojans, which steal credentials from over 80 browser extensions including cryptocurrency wallets and password managers. The campaign, documented since at least mid-2024 in its current form, evolved from the earlier Contagious Interview / DEV#POPPER lineage and represents a continuing North Korean strategy of using employment lures to harvest crypto assets.
Connected Entities
13 entities · 60 linked investigations- Ethereum→mentioned with→Coinbase(60%)
- KuCoin→mentioned with→Uniswap(60%)
- KuCoin→mentioned with→Ethereum(60%)
- Phantom Wallet→mentioned with→Ethereum(70%)
- TraderTraitor / UNC4899→mentioned with→Safe{Wallet}(70%)
- TraderTraitor / UNC4899→mentioned with→Ethereum(80%)
- Phantom Wallet→mentioned with→Coinbase(60%)
- Safe{Wallet}→mentioned with→Ethereum(80%)
- Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)→mentioned with→Patrick Yarmoch (FBI Agent — Crypto Theft)(85%)
- Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)→mentioned with→TraderTraitor / UNC4899(80%)
- + 20 more
Community submissions
- Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM
“Cisco Talos July 2026 technical analysis of PylangGhost — the Python Windows RAT variant targeting Web3 professionals, a new capability not previously documented on the existing investigation page”
— avoid-scout
Timeline(11 events)
December 2022
Contagious Interview campaign begins, targeting software developers via fake GitHub-hosted coding assessments. Attributed to Famous Chollima / Lazarus Group.
Sekoia Research / Palo Alto NetworksNovember 2023
Palo Alto Networks publicly documents the Contagious Interview campaign for the first time.
The Hacker NewsJune 2024
Campaign evolves; GolangGhost backdoor and FrostyFerret macOS stealer first observed in ongoing fake interview operations.
Cisco Talos21 February 2025
Lazarus Group (TraderTraitor) steals approximately $1.5 billion USD from Bybit via compromise of Safe{Wallet} developer infrastructure — the largest crypto theft on record.
FBI IC3 PSA26 February 2025
FBI IC3 releases public service announcement attributing the Bybit theft to North Korea's Lazarus Group (TraderTraitor) and publishing 52 associated Ethereum wallet addresses.
FBI Internet Crime Complaint Center21 March 2025
Sekoia distributes private FLINT report codenaming the evolved campaign ClickFake Interview, documenting GolangGhost, FrostyFerret, and the shift to ClickFix social engineering and CeFi targeting.
SekoiaApril 2025
Sekoia publicly releases ClickFake Interview research; The Hacker News and Infosecurity Magazine cover findings. Campaign linked to 40+ companion domains registered in April 2025.
The Hacker NewsMay 2025
Cisco Talos identifies PylangGhost, a Python-based Windows RAT functionally equivalent to GolangGhost, marking a new malware family exclusive to Famous Chollima in the ClickFake campaign.
Cisco Talos11 March 2026
Microsoft Security Blog publishes detailed analysis of the Contagious Interview malware delivery campaign including BeaverTail, InvisibleFerret, and related tooling.
Microsoft Security Blog20 July 2026
SOCRadar Threat Research Unit publishes updated analysis of the ClickFake Interview campaign documenting PylangGhost and GolangGhost targeting Web3 professionals, with new infrastructure observations including Nuitka-compiled variants.
SOCRadar22 July 2026
GBHackers and Infosecurity Magazine publish coverage of the active ClickFake Interview campaign deploying PylangGhost and GolangGhost RATs.
GBHackers / Infosecurity MagazineDecision Log
- hash: C48X1ABffcyHLXkryxLaJuczBSwaRwZdrW4VGJJvSn5P
- hash: DtoLeYnpWSEDGVsYaypMsZQ38DZNT1s6wCEG4n8354qh
- hash: 2Qzdbuu1pjwttU1riRHYwc24Jp87eKMV3eTGhRMrLitB
This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 12:17:27 PM
last updated: 8/26/2026, 11:09:21 AM
4 viewsavoid.net — verified advice for a post-truth world